Advertisement
Promo

Security threats Toolkit

Worm alert! LOVELETTER gets nastier

Robert Lemos, ZDNet News ZDNet.co.uk

Published: 19 May 2000 08:33 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security software maker Symantec warned computer users and businesses of a new, destructive worm -- apparently based on ILOVEYOU -- that had hit three Israeli and European clients by Thursday night.

Aside from spreading by mailing itself out to everyone on the Outlook address book, the virus also deletes all files on the victim's computer -- and any mapped, network drives -- by setting the files' lengths to zero.

"For most users, if you are infected with the virus, it means you need to have your machine rebuilt," said Vincent Weafer, director of the Symantec AntiVirus Research Centre, referring to rebuilding the computer's files from backup.

The malicious code is mailed to users as an apparent attachment from a friend, with the subject line "FW:" followed by a random file name. The attached file has that name plus the .VBS extension.

For example, the worm might find the file "mydoc.txt" on the user's system and send off a message with the subject line "FW: mydoc.txt" and an attachment of "mydoc.txt.vbs".

The current variant also adds a twist found in other viruses: Polymorphism.

The worm adds a few characters to its script's comment lines, thereby changing the length and "fingerprint" by which most virus software recognises the code for what it is. That feature could make the virus harder to stop.

There are three ways to stop the virus, said Weafer.

  • First, the network administrator can block all e-mail containing VBS scripts.

  • Second, users of Outlook should download Microsoft's newest patch and turn off VBS scripts.

  • Finally, users can turn off the Windows Scripting Host in Windows 98 by using the Control Panel/Add-Remove Programs/Windows Settings Tab/Acessories and uncheck the element "Windows Scripting Host."

Click here for Protection against the dangerous new ILOVEYOU variant.

Would you prosecute British Gas for making it possible to put your head in the oven and turn the gas on? Chris Long is taking no prisoners with this one, he accuses users who got the ILOVEYOU virus of having the IQ equivilent to a pin mould.

What do you think? Tell the Mailroom. And read what others have said.

Go to ZDNet's ILOVEYOU Special Report

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
29 out of 69 people found this useful


Full Talkback thread

1 comment

  1. Think of all the trouble that would be saved if Mi... CyberDAEMON

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

1 comment

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters